Malware.View on attack.mitre.org
SYSCON is a backdoor that has been in use since at least 2017 and has been associated with campaigns involving North Korean themes. SYSCON has been delivered by the CARROTBALL and CARROTBAT droppers.
| Technique | Procedure example |
|---|---|
| T1057 Process Discovery |
SYSCON has the ability to use Tasklist to list running processes. |
| T1059.003 Windows Command Shell |
SYSCON has the ability to execute commands through cmd on a compromised host. |
| T1071.002 File Transfer Protocols |
SYSCON has the ability to use FTP in C2 communications. |
| T1082 System Information Discovery |
SYSCON has the ability to use Systeminfo to identify system information. |
| T1204.002 Malicious File |
SYSCON has been executed by luring victims to open malicious e-mail attachments. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.